Card Not Present Fraud


Card not present fraud (CNP fraud) is the unauthorised use of stolen card credentials in a transaction where the physical card is never presented – online, in-app, over the phone, or by mail order. Because no chip is read and no PIN is entered at a terminal, the payment is authorised on data alone: card number, expiry date, CVV, and whatever contextual signals the merchant and issuer can assemble around them.
A card not present transaction is not suspicious by nature. It is the default shape of e-commerce, recurring billing, BNPL checkout and digital lending disbursement. CNP fraud is simply what happens when the credential is genuine and the person using it is not – and the payment rail has no physical proof either way.
In a card present transaction, the chip performs cryptographic authentication at the terminal. The card proves it is the card. Counterfeiting that is expensive, which is why EMV migration pushed organised fraud into remote channels rather than eliminating it.
In the card not present case, that proof disappears. The issuer is left inferring legitimacy from static data that leaks constantly through breaches, phishing and dark-web resale. Every authentication layer added since – AVS, CVV checks, 3-D Secure, one-time passcodes – is an attempt to rebuild the missing proof out of context rather than out of cryptography at the point of sale.
The transaction is the last step, not the first. Stolen credential sets are usually validated before they are spent: card testing runs small, low-value attempts across merchants with light monitoring, confirming which numbers are live before the working ones are used or resold. By the time a loss appears, the card has often already been tested.
The second route is authentication itself. Social engineering aimed at extracting one-time passcodes lets a fraudster provision stolen card details into a digital wallet or clear a challenge directly. Once the passcode is handed over, the resulting payment reaches the issuer authenticated. Strong customer authentication has been satisfied. The transaction can look cleaner than a legitimate one placed from an unfamiliar browser, and by that point the decision is already lost.
Credential checks remain necessary and are no longer sufficient on their own. CNP fraud prevention depends on evaluating the environment a transaction originates from, not only the data it carries:
A card not present transaction is any payment completed without the physical card being read by a terminal – online checkouts, in-app purchases, phone orders and mail order. The merchant submits card data rather than a chip-authenticated cryptogram, so authorisation depends on data and context alone.
Card present fraud requires physical possession of a card or a counterfeit copy and is limited by geography. Card not present fraud needs only the credential data, scales without physical constraints, and can be executed from anywhere against any remote merchant.
No. CVV confirms the entered code matches issuer records, but breached and phished datasets routinely include it. CVV filters opportunistic attempts and does nothing against validated credential sets, which is why layered CNP fraud detection is standard practice.
By combining credential verification with session-level assessment: device and environment signals, behavioural anomalies, connection analysis and cross-attempt correlation. Prevention works best before authorisation, at login and wallet provisioning, rather than at the transaction alone.

Account takeover turns a trusted login into a fraud event. Learn how attackers compromise accounts, the signals that expose them, and how risk teams stop ATO.

What is bot fraud? How automated scripts attack onboarding, logins, and payments – and how device intelligence helps fraud teams detect and stop them early.

What is device fingerprinting? Learn how it identifies devices, detects fraud patterns, and supports risk decisions in digital finance.
Get a live session with our specialist who will show how your business can detect fraud attempts in real time.
Learn how unique device fingerprints help you link returning users and separate real customers from fraudsters.
Get insights into the main fraud tactics targeting your market — and see how to block them.
Phone:+971 50 371 9151
Email:sales@juicyscore.ai
Our dedicated experts will reach out to you promptly